Forward API リファレンス。
Vault credential object
作成、更新、取得、一覧、およびアーカイブの各エンドポイントはこの構造を返します。token、access_token、refresh_token、client_secret、secret_value などの Credential のシークレットは作成または更新リクエストでのみ受け付けられ、レスポンスには返されません。
| フィールド | 型 | 説明 |
|---|---|---|
id | string | Credential ID with the vcred_ prefix |
type | string | Always "vault_credential" |
vault_id | string | Owning Vault ID |
auth | Credential auth object | Sanitized auth details; secrets are never returned |
display_name | string | 互換性フィールド。現在は常に空文字列で、永続化されません |
metadata | object | Custom metadata object stored with the credential; defaults to {} |
archived_at | string | null | Archive time in RFC 3339 format; null while active |
created_at | string | Creation time in RFC 3339 format |
updated_at | string | Last update time in RFC 3339 format |
Identity の帰属
アカウント(または Workspace)には複数の Identity を作成できます。各 Identity は、そのアカウント(または Workspace)と連携する製品のエンドユーザーを表します。
A Credential does not store ownership separately. It inherits ownership entirely from its Vault:
- Before accessing a Credential, the service checks its Vault against the current ownership scope. In a valid Identity scope, a Vault owned by another Identity returns
404. PAT calls withoutidentity_idand Admin SAT calls retain the existing Owner mismatch403. If this check fails, Credential processing does not continue. - Every Credential in an Identity-owned Vault is visible only to that Identity.
- Create, list, get, update, archive, and delete Credential endpoints support the
identity_idquery parameter with the same semantics as Vaults. See Vault identity ownership.
identity_id is optional and is used only for Identity-owned resources. A PAT can specify it explicitly; omitting it uses the administrator scope. With SAT, issue an Identity-scoped token and do not explicitly pass this parameter; otherwise, the request returns HTTP 400.
Create credential request
| フィールド | 型 | 必須 | 説明 |
|---|---|---|---|
auth | Credential auth object | Yes | Credential authentication information |
metadata | object | No | Custom metadata stored with the credential; defaults to {} |
Credential 更新リクエスト
auth と metadata のみを受け付け、少なくとも 1 つのフィールドが必要です。その他のフィールドを指定すると 400 invalid_request_error が返されます。
| フィールド | 型 | 必須 | 説明 |
|---|---|---|---|
auth | object | いいえ | 認証情報を部分更新します。現在の Credential タイプと一致する type を含める必要があります |
metadata | object | null | いいえ | Merge Patch。オブジェクト内の null は対応するキーを削除し、トップレベルの null は metadata 全体を消去します |
Credential auth object
auth uses type to select the authentication type. Responses never include secret fields.
static_bearer
| フィールド | 型 | 必須 | 説明 |
|---|---|---|---|
type | string | Yes | Always "static_bearer" |
mcp_server_url | string | Yes | MCP server URL, at most 2048 characters |
token | string | Yes (request) | Static Bearer token. Accepted only in create requests and never returned in responses |
mcp_oauth
| フィールド | 型 | 必須 | 説明 |
|---|---|---|---|
type | string | Yes | Always "mcp_oauth" |
mcp_server_url | string | Yes | MCP server URL, at most 2048 characters |
client_id | string | Yes | OAuth client ID |
client_secret | string | Yes (request) | OAuth client secret. Accepted only in create requests and never returned in responses |
access_token | string | No (request) | Access token already obtained through OAuth. Accepted only in create requests and never returned in responses |
refresh_token | string | No (request) | OAuth refresh token. Accepted only in create requests and never returned in responses |
environment_variable
| フィールド | 型 | 必須 | 説明 |
|---|---|---|---|
type | string | はい | 固定値 "environment_variable" |
secret_name | string | はい(作成リクエスト) | 環境変数名。[A-Za-z_][A-Za-z0-9_]* に一致する必要があり、作成後は変更できません |
secret_value | string | はい(作成リクエスト) | 環境変数値。作成または更新リクエストで受け付けられ、レスポンスには返されません |
injection_location | object | いいえ | 注入位置の設定。body と header の boolean フィールドを指定できます |
networking | object | いいえ | ネットワークアクセス制約。unrestricted、または allowed_hosts を持つ limited をサポートします |
The create endpoint for the Forward Credential API defines the supported authentication types. Unlisted types return 400 invalid_request_error during creation.
List pagination fields
| フィールド | 型 | 説明 |
|---|---|---|
data | array of Vault credential objects | Records on the current page |
has_more | boolean | Whether another page is available |
next_page | string | null | Forward cursor for the next page (recommended). Equals the current page's last_id when has_more=true; otherwise null |
first_id | string | null | ID of the first record on the current page |
last_id | string | null | ID of the last record on the current page |
page, after_id, and before_id are mutually exclusive; providing more than one returns 400. Use page where possible; it has the same semantics as after_id.
